Technology · Packagist
feehi/cms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in feehi/cms (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-31353, was published on 6 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest feehi/cms (Packagist) vulnerabilities
- CVE-2026-31353: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category modulelowCVSS 3.1EPSS 0.2%
- CVE-2026-31354: Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions modulelowCVSS 3.1EPSS 0.2%
- CVE-2026-31351: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing modulelowCVSS 3.1EPSS 0.3%
- CVE-2026-31352: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management modulelowCVSS 3.1EPSS 0.2%
- CVE-2026-31350: Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameterlowCVSS 3.1EPSS 0.2%
- CVE-2026-31313: Feehi CMS stored XSS in article content modulemediumCVSS 5.4EPSS 0.2%
- CVE-2025-65657: FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad ManagementlowCVSS 3.1EPSS 0.4%
- CVE-2024-8296: FeehiCMS User[avatar] unrestricted uploadlowCVSS 3.1EPSS 0.8%
- CVE-2024-8295: FeehiCMS BannerForm[img] unrestricted uploadlowCVSS 3.1EPSS 0.8%
- CVE-2024-8294: FeehiCMS file upload vulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2020-21489: Liufee CMS File Upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2020-21174: liufee CMS File Upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2022-43320: FeehiCMS is vulnerable to Cross-Site Scripting (XSS)lowCVSS 3.1EPSS 0.4%
- CVE-2022-38796: Feehi CMS host header injection vulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2020-21516: FeehiCMS has an arbitrary file upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2022-34140: Feehi CMS Cross-site ScriptinglowCVSS 3.1EPSS 4.7%
- CVE-2022-34971: Feehi CMS arbitrary code execution via crafted PHP filelowCVSS 3.1EPSS 1.2%
- CVE-2020-21146: Feehi CMS vulnerable to Cross-site Scripting in Username FieldlowCVSS 3.1EPSS 0.8%
- CVE-2020-22643: Feehi CMS arbitrary file upload vulnerabilitylowCVSS 3.1EPSS 1.9%
- CVE-2020-21322: Arbitrary Code Execution in feehi/cmsinfoEPSS 1.8%
- CVE-2021-30108: Server-Side Request Forgery in Feehi CMSlowCVSS 3.1EPSS 1.1%
Most severe feehi/cms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-31313: Feehi CMS stored XSS in article content modulemediumCVSS 5.4EPSS 0.2%
- CVE-2022-34140: Feehi CMS Cross-site ScriptinglowCVSS 3.1EPSS 4.7%
- CVE-2020-22643: Feehi CMS arbitrary file upload vulnerabilitylowCVSS 3.1EPSS 1.9%
- CVE-2020-21489: Liufee CMS File Upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2020-21174: liufee CMS File Upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2020-21516: FeehiCMS has an arbitrary file upload vulnerabilitylowCVSS 3.1EPSS 1.3%
- CVE-2022-34971: Feehi CMS arbitrary code execution via crafted PHP filelowCVSS 3.1EPSS 1.2%
- CVE-2021-30108: Server-Side Request Forgery in Feehi CMSlowCVSS 3.1EPSS 1.1%
- CVE-2024-8296: FeehiCMS User[avatar] unrestricted uploadlowCVSS 3.1EPSS 0.8%
- CVE-2024-8294: FeehiCMS file upload vulnerabilitylowCVSS 3.1EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/packagist-feehi-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "feehi/cms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/packagist-feehi-cms, 28 September 2026.